8.5.7 (L1) Ensure external participants can't give or request control

Information

This policy setting allows control of who can present in meetings and who can request control of the presentation while a meeting is underway.

Ensuring that only authorized individuals and not external participants are able to present and request control reduces the risk that a malicious user can inadvertently show content that is not appropriate.

External participants are categorized as follows: external users, guests, and anonymous users.

Solution

To remediate using the UI:

- Navigate to Microsoft Teams admin center https://admin.teams.microsoft.com.
- Select Settings & policies > Global (Org-wide default) settings.
- Select Meetings to open the meeting settings section.
- Under content sharing set External participants can give or request control to Off.

To remediate using PowerShell:

- Connect to Teams PowerShell using Connect-MicrosoftTeams.
- Run the following command to set the recommended state:

Set-CsTeamsMeetingPolicy -Identity Global -AllowExternalParticipantGiveRequestControl $false

Impact:

External participants will not be able to present or request control during the meeting.

Warning: This setting also affects webinars.

Note: At this time, to give and take control of shared content during a meeting, both parties must be using the Teams desktop client. Control isn't supported when either party is running Teams in a browser.

See Also

https://workbench.cisecurity.org/benchmarks/24619

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-2

Plugin: microsoft_azure

Control ID: e533188b3f8de3a47785b4f7634cbe57be1c418e9f0e439b1503cf2ad486e83f